This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Brower redirect when using search engine (google)...seems t

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Since yesterday (1/28/10) I noticed that whenever I use Firefox (my preferred browser) and I Google something and click on a link I am redirected to one of those "search for you" sites and occasionally a tab will just suddenly open in the browser and go to one of these random sites (and it always seems to be a progression of jumping thru multiple sites before settling on one of those search sites). I ran an extensive scan using Avast which deleted quit a few suspicious files and it seemed to fix the problem but a few minutes later the problem reoccurred. Then I ran a quick scan using Malwarebytes and it detected 1 file which I removed and, as prompted, I restarted the computer and that still did not fix the program. I then downloaded HijackThis but I am hesitant to delete anything because I read that you could easily delete something important and necessary from your computer. I need help in fixing this problem asap…it is really starting to effect my researching abilities and is terribly annoying!

Thanks!!!!

Here is the log from HijackThis (a side note; I ran this program b4 running Malwarebytes and it ran an log, which I did not save, w/o any issues but after running Malwarebytes and restarting my comp when I ran HijackThis again a prompt popped up stating "For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this problem" this was followed by a prompt on how to fix it that I attempted to follow but for some reason I was not allowed to do what it suggested. I then clicked OK on the pop up and the report below is what ran):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:39:21 AM, on 1/30/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Users\remipmc\Desktop\iWin Games\iWinGamesHookIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\4.0.295.0\npchrome_frame.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.americanpetspa.com
O15 - Trusted IP range: http://71.97.100.63
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O18 - Protocol hijack: cf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E}
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iWinTrusted - iWin Inc. - C:\Users\remipmc\Desktop\iWin Games\iWinTrusted.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

–
End of file - 11918 bytes
Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
OK here are the results….Thanks!

From DDS:



DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 11:17:37.40 on Sat 01/30/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1871 [GMT -6:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Users\remipmc\Desktop\iWin Games\iWinTrusted.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Mozilla Firefox 3.6 Beta 3\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\remipmc\Desktop\dds.com
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
uStart Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\users\remipmc\desktop\iwin games\iWinGamesHookIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\4.0.295.0\npchrome_frame.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\remipmc\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: americanpetspa.com\www
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: cf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\4.0.295.0\npchrome_frame.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\remipmc\appdata\roaming\mozilla\firefox\profiles\x4vqfjcz.default\
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\realarcade\npraclient.dll
FF - plugin: c:\users\remipmc\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\remipmc\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox 3.6 beta 3\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-18 114768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-18 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-18 53328]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-12-10 138680]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 iWinTrusted;iWinTrusted;c:\users\remipmc\desktop\iwin games\iWinTrusted.exe [2009-11-24 78104]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-22 365952]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-12-10 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-12-10 352920]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\drivers\BthAvrcp.sys [2009-8-13 22528]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-22 193840]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [2009-12-21 61952]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 112128]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-29 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2009-7-25 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]

=============== Created Last 30 ================

2010-01-30 08:06:22 3424 ——w- C:\bootsqm.dat
2010-01-30 07:38:36 0 d—–w- c:\program files\Trend Micro
2010-01-30 07:31:51 0 d—–w- c:\users\remipmc\appdata\roaming\Malwarebytes
2010-01-30 07:31:42 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 07:31:40 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-30 07:31:40 0 d—–w- c:\programdata\Malwarebytes
2010-01-30 07:31:40 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 07:20:07 0 d—–w- c:\programdata\Sun
2010-01-30 06:58:39 0 d—–w- c:\program files\SpywareBlaster
2010-01-30 06:55:07 0 d—–w- c:\users\remipmc\.SunDownloadManager
2010-01-29 05:45:53 0 d—–w- c:\users\remipmc\appdata\roaming\Facebook
2010-01-27 04:04:09 0 d—–w- C:\games
2010-01-27 02:59:52 0 d—–w- c:\users\remipmc\appdata\roaming\SevenSails
2010-01-26 22:35:21 285696 —-a-w- c:\windows\system32\winlogon.exe
2010-01-26 22:35:21 2614272 —-a-w- c:\windows\explorer.exe
2010-01-26 04:21:19 0 d—–w- c:\program files\Mary Kay Andrews - The Fixer Upper
2010-01-26 04:15:59 0 d—–w- c:\program files\Sultan's Labyrinth - A Royal Sacrifice
2010-01-26 04:11:31 0 d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2010-01-26 04:01:56 0 d—–w- c:\users\remipmc\appdata\roaming\Green Clover Games
2010-01-26 04:01:56 0 d—–w- c:\programdata\Green Clover Games
2010-01-26 04:00:44 0 d—–w- c:\program files\Rhianna Ford - The Da Vinci Letter
2010-01-26 03:50:51 0 d—–w- c:\program files\Mystery Case Files - Dire Grove
2010-01-23 17:25:55 0 d—–w- c:\windows\Treasure Seekers - The Enchanted Canvases
2010-01-21 22:33:58 977920 —-a-w- c:\windows\system32\wininet.dll
2010-01-21 21:24:36 80915661 —-a-w- c:\users\remipmc\appdata\roaming\The Sultans Labyrinth - A Royal Sacrifice.exe
2010-01-19 04:33:30 0 d—–w- c:\users\remipmc\appdata\roaming\Dragon Altar Games
2010-01-18 18:26:48 0 d—–w- c:\programdata\NOS
2010-01-18 15:37:46 191837285 —-a-w- c:\users\remipmc\appdata\roaming\Rhianna Ford and the Letter from Davinci.exe
2010-01-18 05:10:30 0 d—–w- c:\users\remipmc\appdata\roaming\Orneon
2010-01-18 03:02:30 0 d—–w- c:\programdata\TheFallTrilogy
2010-01-13 04:15:01 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-01-13 04:15:01 108544 —-a-w- c:\windows\system32\t2embed.dll
2010-01-10 04:10:13 0 d—–w- c:\users\remipmc\appdata\roaming\EscapeTheMuseum2
2010-01-10 02:57:41 0 d—–w- c:\users\remipmc\appdata\roaming\Dekovir
2010-01-05 04:00:27 0 d—–w- c:\users\remipmc\appdata\roaming\JoyBits
2010-01-05 03:57:00 0 d—–w- c:\programdata\The Mirror Mysteries
2010-01-05 03:56:32 0 d—–w- c:\program files\The Mirror Mysteries
2010-01-05 03:24:56 0 d—–w- c:\users\remipmc\appdata\roaming\SerpentOfIsis
2010-01-05 02:14:27 0 d—–w- c:\program files\Jewel Quest Mysteries - Trail of the Midnight Heart
2010-01-02 02:15:56 0 d—–w- c:\program files\WiFiConnector

==================== Find3M ====================

2010-01-30 07:19:11 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-14 17:12:06 181120 ——w- c:\windows\system32\MpSigStub.exe
2009-12-21 19:14:26 61952 —-a-w- c:\windows\system32\drivers\bthav.sys
2009-11-18 21:52:26 21316 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 11:18:09.90 ===============

From GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-30 11:38:49
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\remipmc\AppData\Local\Temp\ugldqfod.sys


—- System - GMER 1.0.15 —-

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83045AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83045104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830453F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302D634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8302D898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830451DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83045958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830456F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83045F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 830461A8

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\BTHUSB \Device\00000075 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000077 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8644C856

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001f81000250@0013e0929332 0x6D 0xD4 0x1F 0x6C …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001f81000250@0013e0929332 0x6D 0xD4 0x1F 0x6C …

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

And as per the DDS instructions I zipped the "Attach" file and attached it to this reply.

Once again thanks so much for the help!!

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
OK here is the C:/Combofix.txt:

As a side note while the program was running a message kept popping up (and I mean dozens and dozens of times) stating "Find string (QGREP) Utility has stopped working" and then it would begin to run a Windows diagnostic and say that the program needed to close. I just kept hitting cancel or close program but the scan kept running. I'm not sure if this is important or not but I wanted to let you know. Thanks!!!!


ComboFix 10-01-29.09 - remipmc 01/30/2010 13:41:10.2.1 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1927 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\wuauclt.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-30 19:52 . 2010-01-30 19:52 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-01-30 19:52 . 2010-01-30 19:52 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-30 08:06 . 2010-01-30 08:06 3424 ——w- C:\bootsqm.dat
2010-01-30 07:38 . 2010-01-30 07:38 ——– d—–w- c:\program files\Trend Micro
2010-01-30 07:31 . 2010-01-30 07:31 ——– d—–w- c:\users\remipmc\AppData\Roaming\Malwarebytes
2010-01-30 07:31 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 07:31 . 2010-01-30 07:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 07:31 . 2010-01-30 07:31 ——– d—–w- c:\programdata\Malwarebytes
2010-01-30 07:31 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-30 07:20 . 2010-01-30 07:20 ——– d—–w- c:\program files\Common Files\Java
2010-01-30 06:58 . 2010-01-30 06:58 ——– d—–w- c:\program files\SpywareBlaster
2010-01-30 06:55 . 2010-01-30 06:55 ——– d—–w- c:\users\remipmc\.SunDownloadManager
2010-01-29 05:45 . 2010-01-29 05:45 ——– d—–w- c:\users\remipmc\AppData\Roaming\Facebook
2010-01-27 04:04 . 2010-01-27 04:04 ——– d—–w- C:\games
2010-01-27 02:59 . 2010-01-27 02:59 ——– d—–w- c:\users\remipmc\AppData\Roaming\SevenSails
2010-01-26 22:35 . 2009-10-31 05:45 2614272 —-a-w- c:\windows\explorer.exe
2010-01-26 22:35 . 2009-10-28 06:17 285696 —-a-w- c:\windows\system32\winlogon.exe
2010-01-26 04:21 . 2010-01-26 04:22 ——– d—–w- c:\program files\Mary Kay Andrews - The Fixer Upper
2010-01-26 04:15 . 2010-01-26 04:16 ——– d—–w- c:\program files\Sultan's Labyrinth - A Royal Sacrifice
2010-01-26 04:11 . 2010-01-26 04:13 ——– d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2010-01-26 04:01 . 2010-01-26 04:01 ——– d—–w- c:\users\remipmc\AppData\Roaming\Green Clover Games
2010-01-26 04:01 . 2010-01-26 04:01 ——– d—–w- c:\programdata\Green Clover Games
2010-01-26 04:00 . 2010-01-26 04:01 ——– d—–w- c:\program files\Rhianna Ford - The Da Vinci Letter
2010-01-26 03:50 . 2010-01-26 03:51 ——– d—–w- c:\program files\Mystery Case Files - Dire Grove
2010-01-23 17:25 . 2010-01-23 17:25 ——– d—–w- c:\windows\Treasure Seekers - The Enchanted Canvases
2010-01-21 22:33 . 2009-12-19 09:02 977920 —-a-w- c:\windows\system32\wininet.dll
2010-01-19 04:33 . 2010-01-19 04:33 ——– d—–w- c:\users\remipmc\AppData\Roaming\Dragon Altar Games
2010-01-18 18:36 . 2010-01-18 18:36 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-18 18:29 . 2010-01-18 18:29 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-18 18:26 . 2010-01-21 00:55 ——– d—–w- c:\programdata\NOS
2010-01-18 05:10 . 2010-01-18 05:10 ——– d—–w- c:\users\remipmc\AppData\Roaming\Orneon
2010-01-18 03:02 . 2010-01-18 03:02 ——– d—–w- c:\programdata\TheFallTrilogy
2010-01-13 04:15 . 2009-10-19 14:10 108544 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 04:15 . 2009-10-19 14:10 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-01-10 04:10 . 2010-01-10 04:10 ——– d—–w- c:\users\remipmc\AppData\Roaming\EscapeTheMuseum2
2010-01-10 02:57 . 2010-01-10 02:57 ——– d—–w- c:\users\remipmc\AppData\Roaming\Dekovir
2010-01-05 04:00 . 2010-01-05 04:00 ——– d—–w- c:\users\remipmc\AppData\Roaming\JoyBits
2010-01-05 03:57 . 2010-01-05 03:57 ——– d—–w- c:\programdata\The Mirror Mysteries
2010-01-05 03:56 . 2010-01-05 03:56 ——– d—–w- c:\program files\The Mirror Mysteries
2010-01-05 03:24 . 2010-01-05 03:24 ——– d—–w- c:\users\remipmc\AppData\Roaming\SerpentOfIsis
2010-01-05 02:14 . 2010-01-05 02:15 ——– d—–w- c:\program files\Jewel Quest Mysteries - Trail of the Midnight Heart
2010-01-02 02:15 . 2010-01-02 02:16 ——– d—–w- c:\program files\WiFiConnector

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 07:19 . 2009-07-25 05:18 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-30 07:13 . 2009-08-18 03:40 ——– d—–w- c:\program files\RealArcade
2010-01-30 06:57 . 2009-04-22 15:14 ——– d—–w- c:\program files\Java
2010-01-30 04:01 . 2009-10-29 16:32 ——– d—–w- c:\users\remipmc\AppData\Roaming\Azureus
2010-01-29 22:40 . 2010-01-29 22:40 509552 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb87DA.tmp.exe
2010-01-29 05:45 . 2010-01-29 05:45 50354 —-a-w- c:\users\remipmc\AppData\Roaming\Facebook\uninstall.exe
2010-01-27 03:21 . 2010-01-27 03:21 847040 —-a-w- c:\users\remipmc\AppData\Roaming\Facebook\axfbootloader.dll
2010-01-27 03:20 . 2010-01-27 03:20 5578752 —-a-w- c:\users\remipmc\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
2010-01-26 03:53 . 2009-09-21 02:28 ——– d—–w- c:\users\remipmc\AppData\Roaming\Big Fish Games
2010-01-21 21:24 . 2010-01-21 21:24 80915661 —-a-w- c:\users\remipmc\AppData\Roaming\The Sultans Labyrinth - A Royal Sacrifice.exe
2010-01-21 21:24 . 2010-01-21 21:24 80915661 —-a-w- c:\users\remipmc\AppData\Roaming\The Sultans Labyrinth - A Royal Sacrifice.exe
2010-01-21 00:56 . 2009-10-29 16:28 ——– d—–w- c:\program files\Vuze
2010-01-21 00:56 . 2009-11-15 03:48 177 —-a-w- c:\users\remipmc\AppData\Roaming\Azureus\restart.bat
2010-01-21 00:52 . 2009-04-22 15:13 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-21 00:16 . 2009-09-11 05:30 ——– d—–w- c:\users\remipmc\AppData\Roaming\BitTorrent
2010-01-20 23:37 . 2009-07-25 05:22 ——– d—–w- c:\users\remipmc\AppData\Roaming\LimeWire
2010-01-18 18:43 . 2010-01-18 18:43 75200 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{DE4F3980-D0F0-DCC4-46F1-C4F48F5D2460}-AcroIEHelperShim.dll
2010-01-18 18:43 . 2010-01-18 18:43 61888 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{9A9CA1EF-291D-9561-FF1C-DDBEF121305D}-AcroIEHelper.dll
2010-01-18 18:43 . 2010-01-18 18:43 349616 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{1585BB95-A01E-A157-D382-CD96C12EF227}-AcroRd32.exe
2010-01-18 18:43 . 2010-01-18 18:43 345520 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{1BD4FA73-3E68-CB5F-6F26-8124DCAF32A1}-Setup.exe
2010-01-18 18:27 . 2010-01-18 18:27 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-01-18 15:37 . 2010-01-18 15:37 191837285 —-a-w- c:\users\remipmc\AppData\Roaming\Rhianna Ford and the Letter from Davinci.exe
2010-01-18 15:37 . 2010-01-18 15:37 191837285 —-a-w- c:\users\remipmc\AppData\Roaming\Rhianna Ford and the Letter from Davinci.exe
2010-01-18 02:48 . 2009-08-06 21:04 ——– d—–w- c:\program files\bfgclient
2010-01-17 00:40 . 2010-01-17 00:40 2132480 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{539CB41A-2B4A-6F99-C568-706F495C9482}-qsb.dll
2010-01-14 17:12 . 2009-10-02 16:32 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-14 01:36 . 2009-04-22 14:57 ——– d—–w- c:\programdata\Microsoft Help
2010-01-06 02:59 . 2010-01-06 02:59 83486 —-a-w- c:\programdata\Microsoft\Windows Defender\LocalCopy\{E3278C1B-9795-69CB-9228-CF90A2093CBF}-Uninstall.exe
2010-01-06 02:54 . 2009-09-21 21:16 ——– d—–w- c:\users\remipmc\AppData\Roaming\ERS G-Studio
2010-01-05 01:33 . 2009-08-21 20:07 ——– d—–w- c:\users\remipmc\AppData\Roaming\YoudaGames
2010-01-03 21:11 . 2009-04-22 13:59 ——– d—–w- c:\programdata\Hewlett-Packard
2010-01-03 21:11 . 2009-07-07 15:23 ——– d—–w- c:\program files\Atheros
2009-12-26 22:45 . 2009-12-26 22:44 ——– d—–w- c:\program files\Common Files\Remote Control Software Common
2009-12-26 22:44 . 2009-12-26 22:44 ——– d—–w- c:\program files\Logitech
2009-12-26 22:44 . 2009-04-22 13:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-26 22:43 . 2009-12-26 22:43 ——– d—–w- c:\program files\Common Files\Remote Control USB Driver
2009-12-26 22:41 . 2009-12-26 22:41 ——– d—–w- c:\users\remipmc\AppData\Roaming\InstallShield
2009-12-21 19:14 . 2009-12-21 19:14 61952 —-a-w- c:\windows\system32\drivers\bthav.sys
2009-12-21 02:07 . 2009-11-20 04:11 ——– d—–w- c:\program files\Mozilla Firefox 3.6 Beta 3
2009-12-11 01:15 . 2009-12-11 01:15 ——– d—–w- c:\programdata\Office Genuine Advantage
2009-12-11 01:15 . 2009-07-07 15:24 ——– d—–w- c:\program files\Intel
2009-12-11 01:10 . 2009-11-18 21:16 ——– d—–w- c:\program files\CONEXANT
2009-12-04 01:22 . 2009-12-04 01:22 484976 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbFD64.tmp.exe
2009-11-24 23:54 . 2009-11-19 00:59 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:49 . 2009-11-19 01:00 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-11-19 01:00 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-11-19 00:59 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-11-24 19:42 . 2010-01-30 18:07 1662232 -c—-w- c:\programdata\Microsoft\Windows\WER\ReportQueue\Critical_Windows Defender_8a8e38a98dd13651926ce5f589479478b4fb93_cab_140222d6\iWinGames.exe
2009-11-24 19:41 . 2009-08-27 01:00 46128 —-a-w- c:\programdata\iWin Games\firefox\iWinArcadeLauncher.exe
2009-11-20 11:08 . 2010-01-18 18:29 38784 —-a-w- c:\users\remipmc\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 11:08 . 2010-01-18 18:29 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 23:18 . 2009-11-18 23:18 115904 —-a-w- c:\users\remipmc\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-18 21:52 . 2009-11-18 21:52 21316 —-a-w- c:\windows\system32\emptyregdb.dat
2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}]
2009-09-02 17:29 141312 —-a-w- c:\users\remipmc\Desktop\iWin Games\iWinGamesHookIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-09-30 972080]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-25 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-07-25 122368]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-24 468264]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-08-14 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-08-14 167424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-08-14 144384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

c:\users\remipmc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2006-4-19 1073152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [11/18/2009 6:59 PM 114768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\System32\drivers\vwififlt.sys [7/13/2009 5:52 PM 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [11/18/2009 6:59 PM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [11/18/2009 6:59 PM 53328]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [7/13/2009 5:19 PM 20992]
R2 iWinTrusted;iWinTrusted;c:\users\remipmc\Desktop\iWin Games\iWinTrusted.exe [11/24/2009 1:43 PM 78104]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [4/22/2009 9:17 AM 365952]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\System32\drivers\BthAvrcp.sys [8/13/2009 8:23 AM 22528]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [4/22/2009 8:14 AM 193840]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\System32\drivers\bthav.sys [12/21/2009 1:14 PM 61952]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [6/29/2008 8:52 AM 112128]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/29/2009 6:16 PM 135664]
S3 fssfltr;fssfltr;c:\windows\System32\drivers\fssfltr.sys [7/25/2009 10:35 AM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-30 00:16]

2010-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-30 00:16]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: americanpetspa.com\www
FF - ProfilePath - c:\users\remipmc\AppData\Roaming\Mozilla\Firefox\Profiles\x4vqfjcz.default\
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\RealArcade\npraclient.dll
FF - plugin: c:\users\remipmc\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\remipmc\AppData\Roaming\Move Networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-CNXT_AUDIO_HDA - c:\program files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe



**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8644B856]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
SecurityProcedure -> 0x85755398
QueryNameProcedure -> 0x85755528
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\system32\sppsvc.exe
c:\windows\system32\taskhost.exe
.
**************************************************************************
.
Completion time: 2010-01-30 14:03:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 20:03

Pre-Run: 69,851,893,760 bytes free
Post-Run: 70,028,845,056 bytes free

- - End Of File - - E31106F7A3AEB57AE3FF217B7C993D5C
Hi,

Please run the following tool:


Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

please post the content of that log TDSSKiller
16:53:23:749 4536 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25 16:53:23:749 4536 ================================================================================ 16:53:23:749 4536 SystemInfo: 16:53:23:749 4536 OS Version: 6.1.7600 ServicePack: 0.0 16:53:23:749 4536 Product type: Workstation 16:53:23:749 4536 ComputerName: REMIPMC-PC 16:53:23:756 4536 UserName: remipmc 16:53:23:756 4536 Windows directory: C:\Windows 16:53:23:756 4536 Processor architecture: Intel x86 16:53:23:756 4536 Number of processors: 1 16:53:23:756 4536 Page size: 0x1000 16:53:23:762 4536 Boot type: Normal boot 16:53:23:762 4536 ================================================================================ 16:53:23:765 4536 UnloadDriverW: NtUnloadDriver error 2 16:53:23:765 4536 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 16:53:23:765 4536 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\drivers\klmd.sys) returned status 00000000 16:53:23:784 4536 UtilityInit: KLMD drop and load success 16:53:23:784 4536 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000) 16:53:23:784 4536 UtilityInit: KLMD open success 16:53:23:784 4536 UtilityInit: Initialize success 16:53:23:784 4536 16:53:23:784 4536 Scanning Services … 16:53:23:784 4536 CreateRegParser: Registry parser init started 16:53:23:784 4536 CreateRegParser: DisableWow64Redirection error 16:53:23:784 4536 wfopen_ex: Trying to open file C:\Windows\system32\config\system 16:53:23:785 4536 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\config\system) returned status C0000043 16:53:23:785 4536 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 16:53:23:785 4536 wfopen_ex: Trying to KLMD file open 16:53:23:785 4536 KLMD_CreateFileW: Trying to open file C:\Windows\system32\config\system 16:53:23:785 4536 wfopen_ex: File opened ok (Flags 2) 16:53:23:797 4536 CreateRegParser: HIVE_ADAPTER(C:\Windows\system32\config\system) init success: 1901340 16:53:23:797 4536 wfopen_ex: Trying to open file C:\Windows\system32\config\software 16:53:23:798 4536 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\config\software) returned status C0000043 16:53:23:798 4536 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 16:53:23:798 4536 wfopen_ex: Trying to KLMD file open 16:53:23:798 4536 KLMD_CreateFileW: Trying to open file C:\Windows\system32\config\software 16:53:23:798 4536 wfopen_ex: File opened ok (Flags 2) 16:53:23:820 4536 CreateRegParser: HIVE_ADAPTER(C:\Windows\system32\config\software) init success: 1901368 16:53:23:820 4536 CreateRegParser: EnableWow64Redirection error 16:53:23:820 4536 CreateRegParser: RegParser init completed 16:53:24:824 4536 GetAdvancedServicesInfo: Raw services enum returned 472 services 16:53:24:828 4536 fclose_ex: Trying to close file C:\Windows\system32\config\system 16:53:24:829 4536 fclose_ex: Trying to close file C:\Windows\system32\config\software 16:53:24:829 4536 16:53:24:830 4536 Scanning Kernel memory … 16:53:24:830 4536 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 16:53:24:830 4536 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 865995D0 16:53:24:830 4536 DetectCureTDL3: KLMD_GetDeviceObjectList returned 1 DevObjects 16:53:24:830 4536 16:53:24:830 4536 DetectCureTDL3: DEVICE_OBJECT: 8659A7C8 16:53:24:830 4536 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8659A7C8 16:53:24:830 4536 DetectCureTDL3: DEVICE_OBJECT: 86063908 16:53:24:830 4536 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86063908 16:53:24:830 4536 KLMD_ReadMem: Trying to ReadMemory 0x86063908[0x38] 16:53:24:830 4536 DetectCureTDL3: DRIVER_OBJECT: 8606AC40 16:53:24:830 4536 KLMD_ReadMem: Trying to ReadMemory 0x8606AC40[0xA8] 16:53:24:830 4536 KLMD_ReadMem: Trying to ReadMemory 0x864BE028[0x38] 16:53:24:830 4536 KLMD_ReadMem: Trying to ReadMemory 0x8604CAC0[0xA8] 16:53:24:830 4536 KLMD_ReadMem: Trying to ReadMemory 0x8604B7E0[0x1A] 16:53:24:830 4536 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi 16:53:24:830 4536 DetectCureTDL3: IrpHandler (0) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (1) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (2) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (3) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (4) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (5) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (6) addr: 8644B856 16:53:24:830 4536 DetectCureTDL3: IrpHandler (7) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (8) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (9) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (10) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (11) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (12) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (13) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (14) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (15) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (16) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (17) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (18) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (19) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (20) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (21) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (22) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (23) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (24) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (25) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: IrpHandler (26) addr: 8644B856 16:53:24:831 4536 DetectCureTDL3: All IRP handlers pointed to one addr: 8644B856 16:53:24:831 4536 KLMD_ReadMem: Trying to ReadMemory 0x8644B856[0x400] 16:53:24:831 4536 TDL3_IrpHookDetect: CheckParameters: 4, FFDF0308, 333, 121, 3, 109 16:53:24:831 4536 Driver "atapi" Irp handler infected by TDSS rootkit … 16:53:24:831 4536 KLMD_WriteMem: Trying to WriteMemory 0x8644B8CF[0xD] 16:53:24:831 4536 cured 16:53:24:832 4536 KLMD_ReadMem: Trying to ReadMemory 0x8644B701[0x400] 16:53:24:832 4536 TDL3_StartIoHookDetect: CheckParameters: 9, FFDF0308, 1 16:53:24:832 4536 Driver "atapi" StartIo handler infected by TDSS rootkit … 16:53:24:832 4536 TDL3_StartIoHookCure: Number of patches 1 16:53:24:832 4536 KLMD_WriteMem: Trying to WriteMemory 0x8644B80A[0x6] 16:53:24:832 4536 cured 16:53:24:832 4536 TDL3_FileDetect: Processing driver: atapi 16:53:24:833 4536 TDL3_FileDetect: Processing driver file: C:\Windows\system32\DRIVERS\atapi.sys 16:53:24:833 4536 KLMD_CreateFileW: Trying to open file C:\Windows\system32\DRIVERS\atapi.sys 16:53:24:866 4536 TDL3_FileDetect: C:\Windows\system32\DRIVERS\atapi.sys - Verdict: Infected 16:53:24:866 4536 File C:\Windows\system32\DRIVERS\atapi.sys infected by TDSS rootkit … 16:53:24:866 4536 TDL3_FileCure: Processing driver file: C:\Windows\system32\DRIVERS\atapi.sys 16:53:24:915 4536 FileCallback: Backup candidate found: C:\Windows\system32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys:21584, checking.. 16:53:24:925 4536 ValidateDriverFile: Stage 1 passed 16:53:24:927 4536 ValidateDriverFile: Stage 2 passed 16:53:24:969 4536 DigitalSignVerifyByHandle: Embedded DS result: 00000000 16:53:24:969 4536 ValidateDriverFile: Stage 3 passed 16:53:24:969 4536 FileCallback: File validated successfully, restore information prepared 16:53:25:016 4536 FindDriverFileBackup: Backup copy found in DriverStore 16:53:25:016 4536 TDL3_FileCure: Backup copy found, using it.. 16:53:25:017 4536 TDL3_FileCure: Dumping cured buffer to file C:\Windows\system32\drivers\tsk7477.tmp 16:53:25:049 4536 TDL3_FileCure: New / Old Image paths: (system32\drivers\tsk7477.tmp, system32\drivers\atapi.sys) 16:53:25:049 4536 TDL3_FileCure: KLMD jobs schedule success 16:53:25:049 4536 will be cured on next reboot 16:53:25:049 4536 UtilityBootReinit: Reboot required for cure complete.. 16:53:25:050 4536 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\drivers\klmdb.sys) returned status 00000000 16:53:25:051 4536 UtilityBootReinit: KLMD drop success 16:53:25:051 4536 KLMD_ApplyPendList: Pending buffer(32BE_B24, 616) dropped successfully 16:53:25:051 4536 UtilityBootReinit: Cure on reboot scheduled successfully 16:53:25:051 4536 16:53:25:051 4536 Completed 16:53:25:052 4536 16:53:25:052 4536 Results: 16:53:25:053 4536 Memory objects infected / cured / cured on reboot: 2 / 2 / 0 16:53:25:053 4536 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 16:53:25:053 4536 File objects infected / cured / cured on reboot: 1 / 0 / 1 16:53:25:054 4536 16:53:25:054 4536 UnloadDriverW: NtUnloadDriver error 1 16:53:25:054 4536 KLMD_Unload: UnloadDriverW(klmd21) error 1 16:53:25:055 4536 MyNtCreateFileW: NtCreateFile(\??\C:\Windows\system32\drivers\klmd.sys) returned status 00000000 16:53:25:055 4536 UtilityDeinit: KLMD(ARK) unloaded successfully
Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, January 31, 2010 Operating system: Microsoft Home Edition (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, January 31, 2010 04:24:09 Records in database: 3390485 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 158296 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 13:25:01 No threats found. Scanned area is clean. Selected area has been scanned. Malwarebytes' Anti-Malware 1.44 Database version: 3665 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 1/30/2010 9:58:15 PM mbam-log-2010-01-30 (21-58-15).txt Scan type: Quick Scan Objects scanned: 116544 Time elapsed: 6 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\Temp\winF50B.tmp (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
Please do the following:

submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\windows\system32\wuauclt.exe
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results

Make sure you have copied and saved the results before continuing.


NEXT


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    *wuauclt*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 21:05 on 31/01/2010 by remipmc (Administrator - Elevation successful)

========== filefind ==========

Searching for "*wuauclt*"
C:\Qoobox\Quarantine\C\Windows\System32\wuauclt.exe.vir –a— 47104 bytes [00:14 14/07/2009] [01:14 14/07/2009] B0DA80FF42A0819D162A86612896AAF2
C:\Windows\ERDNT\cache\wuauclt.exe –a— 47104 bytes [20:00 30/01/2010] [01:14 14/07/2009] B0DA80FF42A0819D162A86612896AAF2
C:\Windows\System32\wuauclt.exe —— 47104 bytes [00:14 14/07/2009] [01:14 14/07/2009] B0DA80FF42A0819D162A86612896AAF2
C:\Windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.3.7600.16385_none_3086c9dad36a69b3\wuauclt.exe –a— 47104 bytes [00:14 14/07/2009] [01:14 14/07/2009] B0DA80FF42A0819D162A86612896AAF2

-=End Of File=-


I'm not sure if you need this or not, but this is what the virustotal scan showed after it finished:

MD5: b0da80ff42a0819d162a86612896aaf2
First received: 2009.10.07 12:23:20 UTC
Date: 2010.01.30 14:54:30 UTC [+1D]
Results: 0/41
Permalink: analisis/dac715e415ed0d9e087729542905678d145c5aaa1a2fd57a79cd6f55ee47150c-1264863270
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 21:20:03.98 on Sun 01/31/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3003.1297 [GMT -6:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Users\remipmc\Desktop\iWin Games\iWinTrusted.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\alg.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\remipmc\Desktop\dds.com
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Presario&pf=cnnb
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\users\remipmc\desktop\iwin games\iWinGamesHookIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\4.0.295.0\npchrome_frame.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\remipmc\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: americanpetspa.com\www
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: cf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\4.0.295.0\npchrome_frame.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\remipmc\appdata\roaming\mozilla\firefox\profiles\x4vqfjcz.default\
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\realarcade\npraclient.dll
FF - plugin: c:\users\remipmc\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\remipmc\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox 3.6 beta 3\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox 3.6 beta 3\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox 3.6 beta 3\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-18 114768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-18 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-18 53328]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-12-10 138680]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 iWinTrusted;iWinTrusted;c:\users\remipmc\desktop\iwin games\iWinTrusted.exe [2009-11-24 78104]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-22 365952]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-12-10 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-12-10 352920]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\drivers\BthAvrcp.sys [2009-8-13 22528]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-22 193840]
R3 csr_a2dp;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [2009-12-21 61952]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 112128]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-29 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2009-7-25 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]

=============== Created Last 30 ================

2010-01-31 20:08:35 0 d—–w- c:\users\remipmc\appdata\roaming\TheFixerUpper
2010-01-31 19:29:05 112 —-a-w- c:\users\remipmc\webct_upload_applet.properties
2010-01-31 04:55:01 0 d—–w- c:\program files\Celebrity Toolbar
2010-01-30 20:01:39 0 d-sh–w- C:\$RECYCLE.BIN
2010-01-30 19:29:24 98816 —-a-w- c:\windows\sed.exe
2010-01-30 19:29:24 77312 —-a-w- c:\windows\MBR.exe
2010-01-30 19:29:24 261632 —-a-w- c:\windows\PEV.exe
2010-01-30 19:29:24 161792 —-a-w- c:\windows\SWREG.exe
2010-01-30 08:06:22 3424 ——w- C:\bootsqm.dat
2010-01-30 07:38:36 0 d—–w- c:\program files\Trend Micro
2010-01-30 07:31:51 0 d—–w- c:\users\remipmc\appdata\roaming\Malwarebytes
2010-01-30 07:31:42 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 07:31:40 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-30 07:31:40 0 d—–w- c:\programdata\Malwarebytes
2010-01-30 07:31:40 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 07:20:07 0 d—–w- c:\programdata\Sun
2010-01-30 06:58:39 0 d—–w- c:\program files\SpywareBlaster
2010-01-30 06:55:07 0 d—–w- c:\users\remipmc\.SunDownloadManager
2010-01-29 05:45:53 0 d—–w- c:\users\remipmc\appdata\roaming\Facebook
2010-01-27 04:04:09 0 d—–w- C:\games
2010-01-27 02:59:52 0 d—–w- c:\users\remipmc\appdata\roaming\SevenSails
2010-01-26 22:35:21 285696 —-a-w- c:\windows\system32\winlogon.exe
2010-01-26 22:35:21 2614272 —-a-w- c:\windows\explorer.exe
2010-01-26 04:21:19 0 d—–w- c:\program files\Mary Kay Andrews - The Fixer Upper
2010-01-26 04:15:59 0 d—–w- c:\program files\Sultan's Labyrinth - A Royal Sacrifice
2010-01-26 04:11:31 0 d—–w- c:\program files\Dark Tales - Edgar Allan Poe`s Murders in the Rue Morgue
2010-01-26 04:01:56 0 d—–w- c:\users\remipmc\appdata\roaming\Green Clover Games
2010-01-26 04:01:56 0 d—–w- c:\programdata\Green Clover Games
2010-01-26 04:00:44 0 d—–w- c:\program files\Rhianna Ford - The Da Vinci Letter
2010-01-23 17:25:55 0 d—–w- c:\windows\Treasure Seekers - The Enchanted Canvases
2010-01-21 22:33:58 977920 —-a-w- c:\windows\system32\wininet.dll
2010-01-21 21:24:36 80915661 —-a-w- c:\users\remipmc\appdata\roaming\The Sultans Labyrinth - A Royal Sacrifice.exe
2010-01-19 04:33:30 0 d—–w- c:\users\remipmc\appdata\roaming\Dragon Altar Games
2010-01-18 18:26:48 0 d—–w- c:\programdata\NOS
2010-01-18 15:37:46 191837285 —-a-w- c:\users\remipmc\appdata\roaming\Rhianna Ford and the Letter from Davinci.exe
2010-01-18 05:10:30 0 d—–w- c:\users\remipmc\appdata\roaming\Orneon
2010-01-18 03:02:30 0 d—–w- c:\programdata\TheFallTrilogy
2010-01-13 04:15:01 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-01-13 04:15:01 108544 —-a-w- c:\windows\system32\t2embed.dll
2010-01-10 04:10:13 0 d—–w- c:\users\remipmc\appdata\roaming\EscapeTheMuseum2
2010-01-10 02:57:41 0 d—–w- c:\users\remipmc\appdata\roaming\Dekovir
2010-01-05 04:00:27 0 d—–w- c:\users\remipmc\appdata\roaming\JoyBits
2010-01-05 03:57:00 0 d—–w- c:\programdata\The Mirror Mysteries
2010-01-05 03:56:32 0 d—–w- c:\program files\The Mirror Mysteries
2010-01-05 03:24:56 0 d—–w- c:\users\remipmc\appdata\roaming\SerpentOfIsis
2010-01-05 02:14:27 0 d—–w- c:\program files\Jewel Quest Mysteries - Trail of the Midnight Heart

==================== Find3M ====================

2010-01-30 22:57:57 21584 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-30 07:19:11 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-14 17:12:06 181120 ——w- c:\windows\system32\MpSigStub.exe
2009-12-21 19:14:26 61952 —-a-w- c:\windows\system32\drivers\bthav.sys
2009-11-18 21:52:26 21316 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 21:20:22.67 ===============


Everything seems to be working fine now…yay!! What could have caused the problem? Thank you sooooo much!!!!

Attachments:

  • [attachment removed: Attach__2_.zip]
Hi,

Bit Torrent and Limewire may have had something to do with it. You would be doing yourself a favour to uninstall those programs. You cannot trust the source and many infections come from torrents and peer to peer file sharing.


While you are removing those programs - remove iWin games - this is not a desirable program to have, it comes bundled with adware.

Please go to your windows update and make sure it is working properly

In Windows 7, Windows Update is now part of Action Center. To check for updates, just click the Action Center icon in the taskbar.

[external image: Posted Image]

NEXT

please do the following:


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT


Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • For realtime protection against spyware, try SpywareTerminator


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Let me know if there are any issues with the windows update.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI